> Source: [sk184044](https://support.checkpoint.com/results/sk/sk184044)

# sk184044 - Credential Persistence Limitation for CapsuleVPN with Two-Factor Authentication on Windows 11

| Property | Value |
|----------|-------|
| Solution ID | sk184044 |
| Date Created | 2025-09-30 |
| Last Modified | 2025-10-16 |
| Technical Level | Advanced |
| Products | Spark Firewall (Locally Managed) |
| Versions | R81.10.X |

## Symptoms

- * On Windows 10, when connecting to CapsuleVPN with two-factor authentication (SMS) enabled, users are not prompted for sign-in information. Only the SMS code is requested.
* On Windows 11, when connecting to CapsuleVPN with two-factor authentication (SMS) enabled, users are always prompted for sign-in information (username and password), even if the option to retain credentials is enabled.
* The issue occurs across all firmware versions and on all tested personal computers (PCs).
* Disabling Windows Defender Credential Guard does not resolve the issue.
* Credential persistence works as expected on Windows 11 if two-factor authentication is disabled (credentials are retained for username and password-only login).

## Cause

Windows 11 enforces stricter credential management for Virtual Private Network (VPN) profiles that use two-factor authentication (SMS). When this authentication method is enabled, Windows 11 prevents the saving of user credentials, regardless of the VPN application's settings.  
This platform-level behavior enforced by Microsoft is not specific to CapsuleVPN.  
The Check Point VPN client uses Windows VPN APIs correctly, including setting the RememberCredentials parameter to true. However, Windows 11 overrides this setting for security reasons. This behavior is consistent across all VPN applications that use the Windows VPN APIs.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
